CVE-2026-107655

Source
https://cve.org/CVERecord?id=CVE-2026-107655
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107655.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107655
Aliases
  • GHSA-58wv-9ffm-5w78
Downstream
Published
2026-10-09T08:55:35Z
Modified
2026-10-11T02:46:37Z
Severity
  • 4.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Cups: null pointer dereference via embedded job ticket comments allows remote denial of service
Details

A flaw was found in CUPS. When processing embedded job ticket comments within documents, the service improperly handles specific IPP attributes, causing an unhandled null pointer dereference. An unauthenticated attacker permitted to submit jobs to a shared printer queue can send a crafted Internet Printing Protocol (IPP) request to crash the print daemon, resulting in a temporary Denial of Service (DoS) for all printing services.

Database specific
{
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-476"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107655.json"
}
References

Affected packages

Git / github.com/openprinting/cups

Affected ranges

Type
GIT
Repo
https://github.com/openprinting/cups
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107655.json"